September 11, 2026

When remote access reaches the physical world: Vulnerabilities and consequences

Operator monitoring control systems in a water treatment facility.

Remote access security gaps open the door to damaging cyberattacks, including recent high-visibility incidents targeting critical infrastructure. Here’s a look at the vulnerabilities and consequences at hand.

Most cyberattacks stay digital. Attacks on critical infrastructure may not.

When someone gains access to operational technology (OT), the consequences can reach pumps, valves, treatment processes, and other equipment that communities rely on every day. Recent attacks against U.S. water systems have made that risk unusually visible.

In July 2026, a coordinated cyberattack targeted OT at more than 30 community water systems in Minnesota. The incident followed earlier federal warnings about internet-connected programmable logic controllers (PLCs) being targeted in water and wastewater environments. Between November 2023 and January 2024, CISA documented a campaign that compromised at least 34 PLC devices in U.S. water and wastewater facilities.

The vulnerabilities extend beyond individual attacks. The U.S. Environmental Protection Agency (EPA) says it identified cybersecurity vulnerabilities at 277 water systems during 2025 and worked with those systems to address them.

Removing OT from the public internet wherever possible is an important response. It is also only part of the problem. Utilities still have to operate, maintain, and repair these systems, and that often requires giving employees and outside specialists privileged access.

Critical infrastructure depends on specialized expertise

The U.S. water sector includes close to 170,000 drinking-water and wastewater systems. The U.S. Government Accountability Office has highlighted some of the cybersecurity challenges they face, including aging technology, workforce shortages, limited financial resources, and growing connectivity between OT and internet-enabled systems.

For a small municipal utility, those constraints can make outside expertise especially important.

Picture a pump controller that starts behaving unexpectedly. The utility's staff understands the treatment process, but the person who knows that particular controller best may work for the manufacturer several states away. Giving that technician remote access could be the fastest way to diagnose the problem and restore normal operations.

Similar situations play out across critical infrastructure. Manufacturers turn to OEMs for specialized production equipment, while energy providers may depend on contractors to support assets spread across a large geographic area.

The connection itself is not necessarily the problem. What matters is what happens around it.

A utility needs to know who the technician is and which systems that person actually needs to reach. Access created for an urgent repair should not quietly become permanent access. And if questions arise later, the utility should be able to understand what happened during the session without relying on a shared account name or a vendor's recollection.

Privileged access belongs in the security picture

Traditional OT security controls remain essential. CISA, EPA, and the FBI have advised water systems to reduce unnecessary internet exposure, change default passwords, maintain inventories of OT and IT assets, segment networks, and regularly assess cybersecurity risk.

Once those obvious exposures have been addressed, legitimate users still need a way in.

Privileged access security brings controls to that remaining pathway. It helps organizations manage the identity behind the connection, the systems that person can reach, the credentials involved, and what the user is allowed to do.

Research suggests that both employees and third parties deserve attention.

In a 2025 study conducted by Ponemon Institute on behalf of Imprivata, 47% of organizations said they had experienced a breach or cyberattack involving third-party network access during the previous 12 months. Among organizations that experienced one, 34% said excessive privileged access given to the third party contributed to the incident.

The same study found that 44% experienced a breach or attack involving an internal user with privileged access. Of those organizations, 45% said the employee had been given too much privilege.

The way those users are managed is different.

Internal administrators generally sit inside an organization's existing identity lifecycle. The utility knows who employs them, what job they perform, and when their role changes. Privileged access management can apply stronger controls to the privileged accounts and credentials they use.

Vendor identities are harder to manage because employment and role changes happen outside the utility, even though the access reaches inside its environment. Vendor privileged access management addresses those additional identity, approval, and lifecycle challenges.

Together, privileged access management and vendor privileged access management allow organizations to approach employee and third-party access as parts of a broader privileged access strategy.

The visibility gap is still significant

For water utilities, third-party access can accumulate gradually. One company supports pumps. Another manages instrumentation. A systems integrator works on SCADA. An IT provider supports servers.

Each relationship may have a legitimate reason for remote access. Over time, however, VPN accounts, credentials, vendor-specific tools, and other connections can build up across the organization.

Ponemon respondents estimated that an average of 20 vendors had access to their organization's network. Yet only half said they maintained a comprehensive inventory of all third parties with network access. Fifty-nine percent said third-party access was not monitored.

EPA inspections have found some basic versions of the same access management problem in water systems, including unchanged default passwords, shared staff logins, and access that remained available to former employees.

For security teams, that raises a practical question: Once obvious internet exposure has been removed, how much do you actually know about the privileged access that remains?

Water makes the issue especially visible because the connection between a digital action and a physical consequence is so direct. The same access relationships already exist in manufacturing, energy, healthcare, transportation, and other environments where specialized equipment depends on remote expertise.

Our companion whitepaper, “When remote access reaches the physical world,” takes a deeper look at recent water-sector incidents, Imprivata and industry research, and practical ways to bring stronger control to employee and third-party privileged access across critical infrastructure.

Read the whitepaper

You are currently browsing

Product availability varies by region. Would you like to choose a different region?

No thank you, I'd like to continue